Export limit exceeded: 10228 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (5 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-97165 1 Svenbluege.de 1 Event Gallery For Joomla 2026-09-28 N/A
Joomla Extension - svenbluege.de - Reflected XSS and open redirect in Event Gallery extension < 6.5.0 - The “return” parameter is base64-decoded and written to the “Back” link without being validated.
CVE-2026-100749 1 Svenbluege.de 1 Event Gallery For Joomla 2026-09-28 N/A
Joomla Extension - svenbluege.de - CSRF in backend cleanup actions in Event Gallery extension < 6.5.0 - Only orphaned file entries and shopping carts that are older than 30 days will be deleted.
CVE-2026-100747 1 Svenbluege.de 1 Event Gallery For Joomla 2026-09-28 N/A
Joomla Extension - svenbluege.de - CSRF in image upload in Event Gallery extension < 6.5.0 - Due to lack of an CSRF token check, a third-party site can upload files to an event and overwrite existing files with the same name.
CVE-2026-97164 1 Svenbluege.de 1 Event Gallery For Joomla 2026-09-28 N/A
Joomla Extension - svenbluege.de - Authenticated arbitrary path deletion in `clear cache` task in Event Gallery extension < 6.5.0 - Using the `images` parameter of the `cache.process` task, you can recursively delete any directories that the web server is authorized to write to.
CVE-2026-100748 1 Svenbluege.de 1 Event Gallery For Joomla 2026-09-28 N/A
Joomla Extension - svenbluege.de - CSRF in various cart actions in Event Gallery extension < 6.5.0